{"id":"CVE-2026-58657","aliases":["GHSA-ffmg-hfvg-jhg9"],"url":"https://o3.security/vulnerability/CVE-2026-58657","summary":"Grav - Stored CSS Injection via Markdown Image resize() Action","details":"Grav before 2.0.0 (affected through 2.0.0-rc.9 and the 2.0 branch) contains a stored CSS injection vulnerability in the Markdown image resize() media action. Prior media hardening rejects direct ?style= payloads and unsafe attribute() fallbacks, but the resize() action in Excerpts::processMediaActions() writes caller-controlled values directly into the image's styleAttributes. A lower-privileged content editor who can edit page Markdown can store a crafted image URL with semicolon-delimited CSS declarations in the resize parameters, which are rendered into the final <img style=...> attribute when a higher-privileged reviewer/admin views the page or preview. This does not require JavaScript execution but enables UI redress/overlay and content-manipulation attacks (e.g., a full-viewport fixed overlay). Fixed in 2.0.0.","published":"2026-07-08T13:49:12.183Z","modified":"2026-08-12T03:51:31.310286557Z","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":null,"affectedPackages":[{"ecosystem":"Packagist","name":"getgrav/grav","fixedVersion":"2.0.0"}],"fix":{"url":"https://github.com/getgrav/grav/commit/6582166173bb8eb5869d96aea384e0e73777c94c","label":"getgrav/grav@6582166"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/58xxx/CVE-2026-58657.json"},{"type":"ADVISORY","url":"https://github.com/getgrav/grav/security/advisories/GHSA-ffmg-hfvg-jhg9"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-58657"},{"type":"ADVISORY","url":"https://www.vulncheck.com/advisories/grav-stored-css-injection-via-markdown-image-resize-action"},{"type":"FIX","url":"https://github.com/getgrav/grav/commit/6582166173bb8eb5869d96aea384e0e73777c94c"},{"type":"FIX","url":"https://github.com/getgrav/grav/commit/e03d29aa0d3ece16d73c1ffccfa78df8bf5f28b8"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-12T03:51:31.310286557Z"}}